Vendor CVEs
Microsoft
All CVEs
15,666 total · sorted by risk| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2021-28446 | Hig | 0.46 | 7.1 | 0.01 | Apr 13, 2021 | Windows Portmapping Information Disclosure Vulnerability | ||
| CVE-2021-28440 | Hig | 0.46 | 7.0 | 0.01 | Apr 13, 2021 | Windows Installer Elevation of Privilege Vulnerability | ||
| CVE-2021-27072 | Hig | 0.46 | 7.0 | 0.01 | Apr 13, 2021 | Win32k Elevation of Privilege Vulnerability | ||
| CVE-2021-27055 | Hig | 0.46 | 7.0 | 0.02 | Mar 11, 2021 | Microsoft Visio Security Feature Bypass Vulnerability | ||
| CVE-2021-26873 | Hig | 0.46 | 7.0 | 0.01 | Mar 11, 2021 | Windows User Profile Service Elevation of Privilege Vulnerability | ||
| CVE-2021-26866 | Hig | 0.46 | 7.1 | 0.01 | Mar 11, 2021 | Windows Update Service Elevation of Privilege Vulnerability | ||
| CVE-2021-26863 | Hig | 0.46 | 7.0 | 0.12 | Mar 11, 2021 | Windows Win32k Elevation of Privilege Vulnerability | ||
| CVE-2021-26862 | Hig | 0.46 | 7.0 | 0.01 | Mar 11, 2021 | Windows Installer Elevation of Privilege Vulnerability | ||
| CVE-2021-24095 | Hig | 0.46 | 7.0 | 0.01 | Mar 11, 2021 | DirectX Elevation of Privilege Vulnerability | ||
| CVE-2021-1729 | Hig | 0.46 | 7.1 | 0.01 | Mar 11, 2021 | Windows Update Stack Setup Elevation of Privilege Vulnerability | ||
| CVE-2021-24087 | Hig | 0.46 | 7.0 | 0.00 | Feb 25, 2021 | Azure IoT CLI extension Elevation of Privilege Vulnerability | ||
| CVE-2021-1639 | Hig | 0.46 | 7.0 | 0.02 | Feb 25, 2021 | Visual Studio Code Remote Code Execution Vulnerability | ||
| CVE-2021-1709 | Hig | 0.46 | 7.0 | 0.01 | Jan 12, 2021 | Windows Win32k Elevation of Privilege Vulnerability | ||
| CVE-2021-1682 | Hig | 0.46 | 7.0 | 0.01 | Jan 12, 2021 | Windows Kernel Elevation of Privilege Vulnerability | ||
| CVE-2020-17089 | Hig | 0.46 | 7.1 | 0.03 | Dec 10, 2020 | Microsoft SharePoint Elevation of Privilege Vulnerability | ||
| CVE-2020-17057 | Hig | 0.46 | 7.0 | 0.02 | Nov 11, 2020 | Windows Win32k Elevation of Privilege Vulnerability | ||
| CVE-2020-17007 | Hig | 0.46 | 7.0 | 0.01 | Nov 11, 2020 | Windows Error Reporting Elevation of Privilege Vulnerability | ||
| CVE-2020-16998 | Hig | 0.46 | 7.0 | 0.01 | Nov 11, 2020 | DirectX Elevation of Privilege Vulnerability | ||
| CVE-2020-16977 | Hig | 0.46 | 7.0 | 0.03 | Oct 16, 2020 | A remote code execution vulnerability exists in Visual Studio Code when the Python extension loads a Jupyter notebook file. An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the current user. If the current user is logged on… | ||
| CVE-2020-16969 | Hig | 0.46 | 7.1 | 0.03 | Oct 16, 2020 | An information disclosure vulnerability exists in how Microsoft Exchange validates tokens when handling certain messages. An attacker who successfully exploited the vulnerability could use this to gain further information from a user. To exploit the vulnerability, an… | ||
| CVE-2020-16934 | Hig | 0.46 | 7.0 | 0.03 | Oct 16, 2020 | An elevation of privilege vulnerability exists in the way that Microsoft Office Click-to-Run (C2R) AppVLP handles certain files. An attacker who successfully exploited the vulnerability could elevate privileges. To exploit this vulnerability, an attacker would need to… | ||
| CVE-2020-16933 | Hig | 0.46 | 7.0 | 0.03 | Oct 16, 2020 | A security feature bypass vulnerability exists in Microsoft Word software when it fails to properly handle .LNK files. An attacker who successfully exploited the vulnerability could use a specially crafted file to perform actions in the security context of the current user.… | ||
| CVE-2020-16900 | Hig | 0.46 | 7.0 | 0.01 | Oct 16, 2020 | An elevation of privilege vulnerability exists when the Windows Event System improperly handles objects in memory. To exploit this vulnerability, an attacker would first have to gain execution on the victim system. An attacker could then run a specially crafted… | ||
| CVE-2020-16877 | Hig | 0.46 | 7.1 | 0.01 | Oct 16, 2020 | An elevation of privilege vulnerability exists when Microsoft Windows improperly handles reparse points. An attacker who successfully exploited this vulnerability could overwrite or delete a targeted file that would normally require elevated permissions. To exploit… | ||
| CVE-2020-16876 | Hig | 0.46 | 7.1 | 0.01 | Oct 16, 2020 | An elevation of privilege vulnerability exists when the Windows Application Compatibility Client Library improperly handles registry operations. An attacker who successfully exploited this vulnerability could gain elevated privileges. To exploit the vulnerability, an… | ||
| CVE-2020-1308 | Hig | 0.46 | 7.0 | 0.01 | Sep 11, 2020 | An elevation of privilege vulnerability exists when DirectX improperly handles objects in memory. An attacker who successfully exploited this vulnerability could run arbitrary code in kernel mode. An attacker could then install programs; view, change, or delete data; or… | ||
| CVE-2020-1245 | Hig | 0.46 | 7.0 | 0.01 | Sep 11, 2020 | An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory. An attacker who successfully exploited this vulnerability could run arbitrary code in kernel mode. An attacker could then install programs; view,… | ||
| CVE-2020-16862 | Hig | 0.46 | 7.1 | 0.03 | Sep 11, 2020 | A remote code execution vulnerability exists in Microsoft Dynamics 365 (on-premises) when the server fails to properly sanitize web requests to an affected Dynamics server. An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the… | ||
| CVE-2020-16857 | Hig | 0.46 | 7.1 | 0.03 | Sep 11, 2020 | A remote code execution vulnerability exists in Microsoft Dynamics 365 for Finance and Operations (on-premises) version 10.0.11. An attacker who successfully exploited this vulnerability could gain remote code execution via server-side script execution on the victim… | ||
| CVE-2020-16853 | Hig | 0.46 | 7.1 | 0.01 | Sep 11, 2020 | An elevation of privilege vulnerability exists when the OneDrive for Windows Desktop application improperly handles symbolic links. An attacker who successfully exploited this vulnerability could overwrite a targeted file with an elevated status. To exploit this… | ||
| CVE-2020-16852 | Hig | 0.46 | 7.1 | 0.01 | Sep 11, 2020 | An elevation of privilege vulnerability exists when the OneDrive for Windows Desktop application improperly handles symbolic links. An attacker who successfully exploited this vulnerability could overwrite a targeted file with an elevated status. To exploit this… | ||
| CVE-2020-16851 | Hig | 0.46 | 7.1 | 0.01 | Sep 11, 2020 | An elevation of privilege vulnerability exists when the OneDrive for Windows Desktop application improperly handles symbolic links. An attacker who successfully exploited this vulnerability could overwrite a targeted file with an elevated status. To exploit this… | ||
| CVE-2020-0912 | Hig | 0.46 | 7.0 | 0.01 | Sep 11, 2020 | An elevation of privilege vulnerability exists when the Windows Function Discovery SSDP Provider improperly handles memory. To exploit this vulnerability, an attacker would first have to gain execution on the victim system. An attacker could then run a specially… | ||
| CVE-2020-0878 | Med | 0.46 | 4.2 | 0.03 | KEV | Sep 11, 2020 | A remote code execution vulnerability exists in the way that Microsoft browsers access objects in memory. The vulnerability could corrupt memory in a way that could allow an attacker to execute arbitrary code in the context of the current user. An attacker who successfully… | |
| CVE-2020-1488 | Hig | 0.46 | 7.0 | 0.01 | Aug 17, 2020 | An elevation of privilege vulnerability exists when the Windows AppX Deployment Extensions improperly performs privilege management, resulting in access to system files. To exploit this vulnerability, an authenticated attacker would need to run a specially crafted application to… | ||
| CVE-2020-1477 | Hig | 0.46 | 7.0 | 0.03 | Aug 17, 2020 | A memory corruption vulnerability exists when Windows Media Foundation improperly handles objects in memory. An attacker who successfully exploited the vulnerability could install programs; view, change, or delete data; or create new accounts with full user rights. There are… | ||
| CVE-2020-1473 | Hig | 0.46 | 7.0 | 0.03 | Aug 17, 2020 | A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles objects in memory. An attacker who successfully exploited this vulnerability could execute arbitrary code on a victim system. An attacker could exploit this vulnerability by… | ||
| CVE-2020-1461 | Hig | 0.46 | 7.1 | 0.01 | Jul 14, 2020 | An elevation of privilege vulnerability exists when the MpSigStub.exe for Defender allows file deletion in arbitrary locations.To exploit the vulnerability, an attacker would first have to log on to the system, aka 'Microsoft Defender Elevation of Privilege Vulnerability'. | ||
| CVE-2020-1405 | Hig | 0.46 | 7.1 | 0.01 | Jul 14, 2020 | An elevation of privilege vulnerability exists when Windows Mobile Device Management (MDM) Diagnostics improperly handles junctions, aka 'Windows Mobile Device Management Diagnostics Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-1372. | ||
| CVE-2020-1364 | Hig | 0.46 | 7.1 | 0.01 | Jul 14, 2020 | A denial of service vulnerability exists in the way that the WalletService handles files, aka 'Windows WalletService Denial of Service Vulnerability'. | ||
| CVE-2019-3585 | Hig | 0.46 | 7.0 | 0.00 | Jun 10, 2020 | Privilege Escalation vulnerability in Microsoft Windows client (McTray.exe) in McAfee VirusScan Enterprise (VSE) 8.8 prior to Patch 14 may allow local users to interact with the On-Access Scan Messages - Threat Alert Window with elevated privileges via running McAfee Tray with… | ||
| CVE-2020-1244 | Hig | 0.46 | 7.1 | 0.03 | Jun 9, 2020 | A denial of service vulnerability exists when Connected User Experiences and Telemetry Service improperly handles file operations, aka 'Connected User Experiences and Telemetry Service Denial of Service Vulnerability'. This CVE ID is unique from CVE-2020-1120. | ||
| CVE-2020-1204 | Hig | 0.46 | 7.1 | 0.01 | Jun 9, 2020 | An elevation of privilege vulnerability exists when Windows Mobile Device Management (MDM) Diagnostics improperly handles junctions, aka 'Windows Mobile Device Management Diagnostics Elevation of Privilege Vulnerability'. | ||
| CVE-2020-1073 | Hig | 0.46 | 8.1 | 0.09 | Jun 9, 2020 | A remote code execution vulnerability exists in the way that the ChakraCore scripting engine handles objects in memory, aka 'Scripting Engine Memory Corruption Vulnerability'. | ||
| CVE-2020-1164 | Hig | 0.46 | 7.0 | 0.02 | May 21, 2020 | An elevation of privilege vulnerability exists when the Windows Runtime improperly handles objects in memory. An attacker who successfully exploited this vulnerability could run arbitrary code in an elevated context. An attacker could exploit this vulnerability by running a… | ||
| CVE-2020-1151 | Hig | 0.46 | 7.0 | 0.02 | May 21, 2020 | An elevation of privilege vulnerability exists when the Windows Runtime improperly handles objects in memory. An attacker who successfully exploited this vulnerability could run arbitrary code in an elevated context. An attacker could exploit this vulnerability by running a… | ||
| CVE-2020-1149 | Hig | 0.46 | 7.0 | 0.02 | May 21, 2020 | An elevation of privilege vulnerability exists when the Windows Runtime improperly handles objects in memory. An attacker who successfully exploited this vulnerability could run arbitrary code in an elevated context. An attacker could exploit this vulnerability by running a… | ||
| CVE-2020-1143 | Hig | 0.46 | 7.0 | 0.01 | May 21, 2020 | An elevation of privilege vulnerability exists in Windows when the Windows kernel-mode driver fails to properly handle objects in memory. An attacker who successfully exploited this vulnerability could run arbitrary code in kernel mode. An attacker could then install programs;… | ||
| CVE-2020-1138 | Hig | 0.46 | 7.0 | 0.01 | May 21, 2020 | An elevation of privilege vulnerability exists when the Storage Service improperly handles file operations. An attacker who successfully exploited this vulnerability could gain elevated privileges on the victim system. To exploit the vulnerability, an attacker would first have… | ||
| CVE-2020-1132 | Hig | 0.46 | 7.0 | 0.01 | May 21, 2020 | An elevation of privilege vulnerability exists when Windows Error Reporting manager improperly handles file and folder links. An attacker who successfully exploited this vulnerability could overwrite a targeted file leading to an elevated status. To exploit this vulnerability,… |
- risk 0.46cvss 7.1epss 0.01
Windows Portmapping Information Disclosure Vulnerability
- risk 0.46cvss 7.0epss 0.01
Windows Installer Elevation of Privilege Vulnerability
- risk 0.46cvss 7.0epss 0.01
Win32k Elevation of Privilege Vulnerability
- risk 0.46cvss 7.0epss 0.02
Microsoft Visio Security Feature Bypass Vulnerability
- risk 0.46cvss 7.0epss 0.01
Windows User Profile Service Elevation of Privilege Vulnerability
- risk 0.46cvss 7.1epss 0.01
Windows Update Service Elevation of Privilege Vulnerability
- risk 0.46cvss 7.0epss 0.12
Windows Win32k Elevation of Privilege Vulnerability
- risk 0.46cvss 7.0epss 0.01
Windows Installer Elevation of Privilege Vulnerability
- risk 0.46cvss 7.0epss 0.01
DirectX Elevation of Privilege Vulnerability
- risk 0.46cvss 7.1epss 0.01
Windows Update Stack Setup Elevation of Privilege Vulnerability
- risk 0.46cvss 7.0epss 0.00
Azure IoT CLI extension Elevation of Privilege Vulnerability
- risk 0.46cvss 7.0epss 0.02
Visual Studio Code Remote Code Execution Vulnerability
- risk 0.46cvss 7.0epss 0.01
Windows Win32k Elevation of Privilege Vulnerability
- risk 0.46cvss 7.0epss 0.01
Windows Kernel Elevation of Privilege Vulnerability
- risk 0.46cvss 7.1epss 0.03
Microsoft SharePoint Elevation of Privilege Vulnerability
- risk 0.46cvss 7.0epss 0.02
Windows Win32k Elevation of Privilege Vulnerability
- risk 0.46cvss 7.0epss 0.01
Windows Error Reporting Elevation of Privilege Vulnerability
- risk 0.46cvss 7.0epss 0.01
DirectX Elevation of Privilege Vulnerability
- risk 0.46cvss 7.0epss 0.03
A remote code execution vulnerability exists in Visual Studio Code when the Python extension loads a Jupyter notebook file. An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the current user. If the current user is logged on…
- risk 0.46cvss 7.1epss 0.03
An information disclosure vulnerability exists in how Microsoft Exchange validates tokens when handling certain messages. An attacker who successfully exploited the vulnerability could use this to gain further information from a user. To exploit the vulnerability, an…
- risk 0.46cvss 7.0epss 0.03
An elevation of privilege vulnerability exists in the way that Microsoft Office Click-to-Run (C2R) AppVLP handles certain files. An attacker who successfully exploited the vulnerability could elevate privileges. To exploit this vulnerability, an attacker would need to…
- risk 0.46cvss 7.0epss 0.03
A security feature bypass vulnerability exists in Microsoft Word software when it fails to properly handle .LNK files. An attacker who successfully exploited the vulnerability could use a specially crafted file to perform actions in the security context of the current user.…
- risk 0.46cvss 7.0epss 0.01
An elevation of privilege vulnerability exists when the Windows Event System improperly handles objects in memory. To exploit this vulnerability, an attacker would first have to gain execution on the victim system. An attacker could then run a specially crafted…
- risk 0.46cvss 7.1epss 0.01
An elevation of privilege vulnerability exists when Microsoft Windows improperly handles reparse points. An attacker who successfully exploited this vulnerability could overwrite or delete a targeted file that would normally require elevated permissions. To exploit…
- risk 0.46cvss 7.1epss 0.01
An elevation of privilege vulnerability exists when the Windows Application Compatibility Client Library improperly handles registry operations. An attacker who successfully exploited this vulnerability could gain elevated privileges. To exploit the vulnerability, an…
- risk 0.46cvss 7.0epss 0.01
An elevation of privilege vulnerability exists when DirectX improperly handles objects in memory. An attacker who successfully exploited this vulnerability could run arbitrary code in kernel mode. An attacker could then install programs; view, change, or delete data; or…
- risk 0.46cvss 7.0epss 0.01
An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory. An attacker who successfully exploited this vulnerability could run arbitrary code in kernel mode. An attacker could then install programs; view,…
- risk 0.46cvss 7.1epss 0.03
A remote code execution vulnerability exists in Microsoft Dynamics 365 (on-premises) when the server fails to properly sanitize web requests to an affected Dynamics server. An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the…
- risk 0.46cvss 7.1epss 0.03
A remote code execution vulnerability exists in Microsoft Dynamics 365 for Finance and Operations (on-premises) version 10.0.11. An attacker who successfully exploited this vulnerability could gain remote code execution via server-side script execution on the victim…
- risk 0.46cvss 7.1epss 0.01
An elevation of privilege vulnerability exists when the OneDrive for Windows Desktop application improperly handles symbolic links. An attacker who successfully exploited this vulnerability could overwrite a targeted file with an elevated status. To exploit this…
- risk 0.46cvss 7.1epss 0.01
An elevation of privilege vulnerability exists when the OneDrive for Windows Desktop application improperly handles symbolic links. An attacker who successfully exploited this vulnerability could overwrite a targeted file with an elevated status. To exploit this…
- risk 0.46cvss 7.1epss 0.01
An elevation of privilege vulnerability exists when the OneDrive for Windows Desktop application improperly handles symbolic links. An attacker who successfully exploited this vulnerability could overwrite a targeted file with an elevated status. To exploit this…
- risk 0.46cvss 7.0epss 0.01
An elevation of privilege vulnerability exists when the Windows Function Discovery SSDP Provider improperly handles memory. To exploit this vulnerability, an attacker would first have to gain execution on the victim system. An attacker could then run a specially…
- risk 0.46cvss 4.2epss 0.03
A remote code execution vulnerability exists in the way that Microsoft browsers access objects in memory. The vulnerability could corrupt memory in a way that could allow an attacker to execute arbitrary code in the context of the current user. An attacker who successfully…
- risk 0.46cvss 7.0epss 0.01
An elevation of privilege vulnerability exists when the Windows AppX Deployment Extensions improperly performs privilege management, resulting in access to system files. To exploit this vulnerability, an authenticated attacker would need to run a specially crafted application to…
- risk 0.46cvss 7.0epss 0.03
A memory corruption vulnerability exists when Windows Media Foundation improperly handles objects in memory. An attacker who successfully exploited the vulnerability could install programs; view, change, or delete data; or create new accounts with full user rights. There are…
- risk 0.46cvss 7.0epss 0.03
A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles objects in memory. An attacker who successfully exploited this vulnerability could execute arbitrary code on a victim system. An attacker could exploit this vulnerability by…
- risk 0.46cvss 7.1epss 0.01
An elevation of privilege vulnerability exists when the MpSigStub.exe for Defender allows file deletion in arbitrary locations.To exploit the vulnerability, an attacker would first have to log on to the system, aka 'Microsoft Defender Elevation of Privilege Vulnerability'.
- risk 0.46cvss 7.1epss 0.01
An elevation of privilege vulnerability exists when Windows Mobile Device Management (MDM) Diagnostics improperly handles junctions, aka 'Windows Mobile Device Management Diagnostics Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-1372.
- risk 0.46cvss 7.1epss 0.01
A denial of service vulnerability exists in the way that the WalletService handles files, aka 'Windows WalletService Denial of Service Vulnerability'.
- risk 0.46cvss 7.0epss 0.00
Privilege Escalation vulnerability in Microsoft Windows client (McTray.exe) in McAfee VirusScan Enterprise (VSE) 8.8 prior to Patch 14 may allow local users to interact with the On-Access Scan Messages - Threat Alert Window with elevated privileges via running McAfee Tray with…
- risk 0.46cvss 7.1epss 0.03
A denial of service vulnerability exists when Connected User Experiences and Telemetry Service improperly handles file operations, aka 'Connected User Experiences and Telemetry Service Denial of Service Vulnerability'. This CVE ID is unique from CVE-2020-1120.
- risk 0.46cvss 7.1epss 0.01
An elevation of privilege vulnerability exists when Windows Mobile Device Management (MDM) Diagnostics improperly handles junctions, aka 'Windows Mobile Device Management Diagnostics Elevation of Privilege Vulnerability'.
- risk 0.46cvss 8.1epss 0.09
A remote code execution vulnerability exists in the way that the ChakraCore scripting engine handles objects in memory, aka 'Scripting Engine Memory Corruption Vulnerability'.
- risk 0.46cvss 7.0epss 0.02
An elevation of privilege vulnerability exists when the Windows Runtime improperly handles objects in memory. An attacker who successfully exploited this vulnerability could run arbitrary code in an elevated context. An attacker could exploit this vulnerability by running a…
- risk 0.46cvss 7.0epss 0.02
An elevation of privilege vulnerability exists when the Windows Runtime improperly handles objects in memory. An attacker who successfully exploited this vulnerability could run arbitrary code in an elevated context. An attacker could exploit this vulnerability by running a…
- risk 0.46cvss 7.0epss 0.02
An elevation of privilege vulnerability exists when the Windows Runtime improperly handles objects in memory. An attacker who successfully exploited this vulnerability could run arbitrary code in an elevated context. An attacker could exploit this vulnerability by running a…
- risk 0.46cvss 7.0epss 0.01
An elevation of privilege vulnerability exists in Windows when the Windows kernel-mode driver fails to properly handle objects in memory. An attacker who successfully exploited this vulnerability could run arbitrary code in kernel mode. An attacker could then install programs;…
- risk 0.46cvss 7.0epss 0.01
An elevation of privilege vulnerability exists when the Storage Service improperly handles file operations. An attacker who successfully exploited this vulnerability could gain elevated privileges on the victim system. To exploit the vulnerability, an attacker would first have…
- risk 0.46cvss 7.0epss 0.01
An elevation of privilege vulnerability exists when Windows Error Reporting manager improperly handles file and folder links. An attacker who successfully exploited this vulnerability could overwrite a targeted file leading to an elevated status. To exploit this vulnerability,…
Page 150 of 314